Digital Evidence Checklist After a Cyber Incident

Practical steps to preserve useful evidence before logs, messages, devices or account records are lost.

First 30 minutes: preserve before changing

  1. Write a simple timeline
    Record when the issue was first noticed, who saw it, what systems were affected and what actions have already been taken.
  2. Capture visible evidence
    Take screenshots or photos of ransom notes, suspicious messages, login alerts, bank details, error screens and URLs.
  3. Keep originals
    Do not delete phishing emails, scam chats, invoices, attachments, browser history or log files until copies are preserved.
  4. Use trusted channels
    Contact banks, platforms and providers through official websites or phone numbers, not links inside suspicious messages.

Evidence checklist

  • Original emails and headers
  • SMS/chat records
  • Web links and screenshots
  • Login and account activity
  • Mailbox rules and forwarding
  • Payment records and invoices
  • Device names and serial numbers
  • Cloud sharing records
  • Security alerts and logs
  • People affected and dates

What not to do too quickly

Avoid factory resets, reinstalling systems, deleting accounts, clearing browser history, wiping phones, paying ransom demands or contacting suspected attackers without advice. These actions can make recovery, reporting or evidence review harder.

Send an evidence-aware enquiry

Related help

Evidence checklist

A practical list of what to preserve before logs, screenshots or account records disappear.

Need clear next steps?

Speak with a digital forensic specialist before evidence is lost.

Tell us what happened, what devices or accounts are involved, and how urgent it is. We will help you frame the right response.

Request a consultation